#VU28410 Input validation error in Linux kernel - CVE-2013-1798
Published: March 22, 2013 / Updated: July 20, 2020
Linux kernel
Linux Foundation
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The ioapic_read_indirect function in virt/kvm/ioapic.c in the Linux kernel through 3.8.4 does not properly handle a certain combination of invalid IOAPIC_REG_SELECT and IOAPIC_REG_WINDOW operations, which allows guest OS users to obtain sensitive information from host OS memory or cause a denial of service (host OS OOPS) via a crafted application.
Remediation
External links
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.103
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.19
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.3
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.214
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.171
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6